Executive brief
A vulnerability was identified in the Linux kernel's Qualcomm IPC Router (QRTR) nameservice driver. This component manages communication between different processors on a device. A flaw during the driver's shutdown process could allow a system crash or unpredictable behavior if network data arrives at the exact moment the driver is being removed.
Technical details
A use-after-free (UAF) vulnerability exists in net/qrtr/ns.c within the Linux kernel. The issue occurs in the driver's remove callback: if a packet arrives after destroy_workqueue() is called but before sock_release(), the qrtr_ns_data_ready() callback attempts to queue work on the already destroyed workqueue. This leads to a dereference of a freed or invalid work struct. The fix involves restoring the default 'sk_data_ready' callback at the beginning of the removal process and ensuring RX threads complete before workqueue destruction. This vulnerability is primarily reachable during module unloading or system shutdown.
Affected products
- Linux Linux Kernel versions prior to 6.9 (specifically affecting qrtr ns)
Timeline
- 2026-04-09: other: Patch submitted by developer
- 2026-05-27: advisory: CVE-2026-46047 published
References
- https://git.kernel.org/stable/c/0f313eb6a8f6dffa491373cf3afab979fa1c02f4
- https://git.kernel.org/stable/c/2e127ceb1c415e246076d8e09e23e443a7a2038f
- https://git.kernel.org/stable/c/7809fea20c9404bfcfa6112ec08d1fe1d3520beb
- https://git.kernel.org/stable/c/db3c60ec772de30acae92d560dfcc5258e58dbe8
- https://git.kernel.org/stable/c/f96779e916576e81430ebb326baff6e433fef8ae